Publication Details

Comparative Analysis of DNS over HTTPS Detectors

JEŘÁBEK Kamil, HYNEK Karel and RYŠAVÝ Ondřej. Comparative Analysis of DNS over HTTPS Detectors. The International Journal of Computer and Telecommunications Networking, vol. 2024, no. 247, pp. 110452-110465. ISSN 1389-1286. Available from: https://doi.org/10.1016/j.comnet.2024.110452
Type
journal article
Language
english
Authors
Jeřábek Kamil, Ing., Ph.D. (DIFS FIT BUT)
Hynek Karel, Ing. (FIT CTU)
Ryšavý Ondřej, doc. Ing., Ph.D. (DIFS FIT BUT)
URL
Keywords

DNS over HTTPS,DoH, detection,comparative analysis,machine learning,network security

Abstract

DNS over HTTPS (DoH) is a protocol that encrypts DNS traffic to improve user privacy and security. However, its use also poses challenges for network operators and security analysts who need to detect and monitor network traffic for security purposes. Therefore, there are multiple DoH detection proposals that leverage machine learning to identify DoH connections; however, these proposals were often tested on different datasets, and their evaluation methodologies were not consistent enough to allow direct performance comparison. We recreated seven DoH detection proposals and evaluated them using six different experiments to answer research questions that targeted specific deployment scenarios concerning ML-model transferability, usability, and longevity. For thorough testing, we used a large Collection of DoH datasets along with a novel 5-week dataset that enabled the evaluation of data drift. Our study provides insights into the current state of DoH detection techniques and can help network operators and security analysts choose the most suitable method for their specific needs.

Published
2024
Pages
110452-110465
Journal
The International Journal of Computer and Telecommunications Networking, vol. 2024, no. 247, ISSN 1389-1286
Publisher
Elsevier Science
DOI
BibTeX
@ARTICLE{FITPUB13072,
   author = "Kamil Je\v{r}\'{a}bek and Karel Hynek and Ond\v{r}ej Ry\v{s}av\'{y}",
   title = "Comparative Analysis of DNS over HTTPS Detectors",
   pages = "110452--110465",
   journal = "The International Journal of Computer and Telecommunications Networking",
   volume = 2024,
   number = 247,
   year = 2024,
   ISSN = "1389-1286",
   doi = "10.1016/j.comnet.2024.110452",
   language = "english",
   url = "https://www.fit.vut.cz/research/publication/13072"
}
Back to top